SOCFRAME / THRONE Journal
All reports

Scenario 04 · Espionage · menuPass / Stone Panda / APT10

Backdoor accounts and
silent services. Flagged.

menuPass builds its foothold quietly — a new local account that answers to no one, a service that starts itself at boot, an admin share mapped for the next hop. We ran that persistence-and-lateral-prep tradecraft end to end on a live Windows victim to exercise techniques our earlier scenarios never touched. THRONE flagged all six actions, mapped each to ATT&CK, and ONYX folded them into a single incident — with no analyst in the loop until there was one thread worth reading.

Adversary
menuPass · APT10
Attribution
China · G0045
Focus
Persistence + lateral prep
Result
Detected end to end
Executive summary

Six quiet moves, one incident

menuPass — also tracked as Stone Panda and APT10 — is one of China's longest-running espionage crews, best known for hollowing out managed service providers and island-hopping into their customers. Its edge is not noise; it is patience and native Windows tooling. We emulated the persistence-and-lateral-prep core of that tradecraft and watched THRONE catch every step.

On a single Windows host we executed six of the group's signature living-off-the-land actions: enumerate the session's privileges, stand up a new local account, promote it into the local Administrators group, install a self-starting service, map a remote SMB admin share to stage the next hop, and decode a base64 payload through a trusted Microsoft binary. Each is designed to look like ordinary administration. Taken together they are a privileged backdoor, a reboot-proof persistence mechanism and a lateral-movement beachhead.

THRONE fired six detections — three HIGH, two MED, one LOW — each mapped to a distinct ATT&CK technique. Five of the six were detection types this campaign had never triggered before, which was the whole point of the run: surface the persistence and lateral-prep signals the earlier scenarios never produced. ONYX then triaged the burst automatically and collapsed it into one credential-access / persistence incident, INC-55843, rather than leaving six disconnected alerts for an analyst to reassemble by hand.

6
Techniques executed
6
Detections fired
5
New detection types
1
Incident (INC-55843)
The adversary

menuPass / Stone Panda / APT10 (G0045)

A China-nexus espionage group tracked by MITRE ATT&CK as G0045 and active since at least 2009. Its defining campaign redefined supply-chain intrusion; its tradecraft is a masterclass in looking like a system administrator.

Attribution

menuPass — variously called Stone Panda, Red Apollo, POTASSIUM, Cicada and Bronze Riverside — is widely assessed to operate in support of Chinese state intelligence requirements. In December 2018 the US Department of Justice indicted two members of the group, alleging they acted in association with the Chinese Ministry of State Security's Tianjin State Security Bureau. The group's remit is classic strategic espionage: aerospace, defense, government, engineering, telecommunications, biotech, healthcare and the managed-service-provider ecosystem that stitches those sectors together. The objective is intellectual property and long-term access, not disruption.

Operation Cloud Hopper

APT10's signature operation, publicly detailed in 2017, targeted managed IT service providers rather than their ultimate victims directly. By compromising an MSP, the group inherited that provider's trusted, privileged connectivity into dozens of downstream customer networks — then island-hopped from one to the next. In ATT&CK terms this is T1199 (Trusted Relationship): abuse the supplier to reach the customer. It is the strategic reason this scenario matters — the lateral-prep moves we emulated are exactly how a foothold on one managed host becomes a foothold on the next.

Signature tradecraft

APT10 favours stealth and long dwell time. Initial access typically arrives as a spearphishing attachment (T1566.001). A hallmark of the group is DLL side-loading (T1574.002) — dropping a legitimately signed executable next to a malicious DLL so a trusted process loads the attacker's code. From there the group leans heavily on living-off-the-land: the native net, wmic, sc and PowerShell utilities, scheduled tasks and services for persistence, and signed system binaries such as certutil for staging and decoding. Its malware family tree includes the shared RAT PlugX, plus RedLeaves, ChChes, QuasarRAT, SodaMaster and the Ecipekac/ANEL loader chains. Credential theft, archived-and-encrypted staging, and exfiltration over HTTPS round out the pattern.

Why these six techniques

The moves in this scenario are not exotic malware — they are the quiet administrative actions APT10 uses to turn one compromised host into durable, privileged, lateral access. A backdoor local admin survives credential resets; a service survives reboots; an admin-share mount is the on-ramp to the next machine; and certutil decoding lets a next-stage payload arrive as harmless-looking text. Detecting them is detecting APT10's actual working style, not a lab artefact.

Setup & methodology

How the run actually worked

No autonomous command-and-control, no embellishment: this was a direct, hand-executed run of menuPass's persistence-and-lateral-prep tradecraft on one instrumented Windows host, cleaned back to baseline afterwards. What we are measuring is the telemetry each action threw and whether THRONE caught it.

The victim

Everything ran on a single lab host, WIN-J50RP1JBGD4 (external 204.168.192.149 · internal 10.0.0.5), running Microsoft Sysmon with process-creation, network-connection and file-create logging. We chose direct execution on purpose: the objective was to exercise persistence and lateral-movement techniques the earlier campaign scenarios never produced — not to demonstrate autonomous planning. This is a lab environment, so the real hostname and IP addresses are shown exactly as captured; nothing is redacted.

Clean-up

The host was fully restored after the run. The backdoor local account was deleted, the persistence service was stopped and removed, the scheduled task was unregistered, and the decoded payload artefact was cleared — the box was returned to its pre-run baseline.

The detection pipeline

Each action on the victim produced a Sysmon event — predominantly Event ID 1 (process creation), carrying the full command line, the parent process, file hashes and, critically, the ProcessGuid and ParentProcessGuid that later let THRONE rebuild causality. Those events are forwarded as tenant-tagged syslog to THRONE's ingest and travel the full pipeline in seconds:

Technique on WIN-J50RP1JBGD4 → Sysmon event (EID 1 / 3 / 11)
→ tenant-tagged syslog → THRONE :1514 → Kafka → ch_pump parse → ClickHouse
→ Sigma sweep (3,148 rules · 389 ATT&CK techniques) + behavioral engine → alert
→ ONYX auto-triage & grouping → INC-55843 → causality tree

The ch_pump parser normalises each raw event and lands it in ClickHouse, where the Sigma sweep evaluates it against 3,148 detection rules spanning 389 ATT&CK techniques, alongside a behavioral engine that scores sequences rather than single events. Any match becomes an alert; ONYX then triages and groups the alerts into an incident. The tenant tag is what keeps this run isolated to its own cloud tenant end to end — every event, alert and the resulting incident stay scoped to the one tenant throughout.

The kill chain

Six phases, step by step

Each action below is a real menuPass behaviour, mapped to its ATT&CK technique, with what the command actually does and why this adversary reaches for it. THRONE detected every one.

Detected
Discoverywhoami /priv
Detected
Persistencenet user /add
Detected
Persistencenet localgroup Administrators
Detected
Persistenceservice install
Detected
Lateral movementnet use · admin$
Detected
Defense evasioncertutil -decode

1 · Discovery — privilege enumeration T1033

whoami /priv lists the security privileges held by the current access token — entries such as SeDebugPrivilege, SeBackupPrivilege or SeImpersonatePrivilege. Before an intruder tries to persist or pivot, they want to know what the current context can already do. APT10 operators favour this kind of quiet, native reconnaissance because it touches no new binaries and generates no network traffic — it simply reads state. The answer tells them whether they can skip privilege escalation entirely.

2 · Persistence — create a local account T1136.001

net user <name> <password> /add creates a new local user. For menuPass this is a backdoor that outlives the initial foothold: it survives a reboot, it survives the owner changing a compromised domain password, and it blends in with the dozens of service and admin accounts a real Windows host accumulates over its life. A new account is cheap to create and expensive to notice.

3 · Persistence — promote to Administrators T1098

net localgroup Administrators <name> /add adds the new account to the local Administrators group. A backdoor is only useful if it is privileged. This single command converts a throwaway user into a local admin that can install software, read any file, manipulate services and authenticate to admin shares on other hosts — the hinge between persistence and lateral movement.

4 · Persistence — install a self-starting service T1543.003

Installing a Windows service (via sc create and the service control manager) gives the adversary code that runs automatically, typically with SYSTEM-level rights, every time the machine boots — no user login required. Services are a classic APT10 persistence mechanism precisely because they are legitimate and ubiquitous; a single rogue service hides comfortably among the hundreds a Windows host already runs.

5 · Lateral movement — map an SMB admin share T1021.002

net use \\<host>\admin$ authenticates to the hidden administrative share on a remote machine over SMB (TCP 445). This is the on-ramp to the next host: once an admin share is mapped, the attacker can stage a payload, copy a service binary, or execute remotely. For a group whose entire reputation is island-hopping from MSP to customer, admin-share access is the move that turns one compromised box into two.

6 · Defense evasion — decode a payload with certutil T1140

certutil -decode takes a base64- or hex-encoded file and writes out its decoded contents. certutil is a Microsoft-signed, always-present certificate utility, which is exactly why it is abused: a next-stage payload can travel and sit on disk as innocuous-looking text, then be reconstituted by a trusted system binary rather than a flagged downloader. It is living-off-the-land defense evasion in a single line.

What THRONE detected

Six alerts, every one mapped

Six alerts fired as the sequence ran on WIN-J50RP1JBGD4, each mapped to an ATT&CK technique and grouped under INC-55843. Shown exactly as captured:

AlertDetectionSevATT&CK
ALR-175448Suspicious New Service CreationHIGHT1543.003
ALR-175453File Decoded From Base64/Hex Via Certutil.EXEHIGHT1140
ALR-175451Security Privileges Enumeration Via Whoami.EXEHIGHT1033
ALR-175452New User Created Via Net.EXEMEDT1136.001
ALR-175449User Added to Local Administrators GroupMEDT1098
ALR-175450Windows Share Mount Via Net.EXELOWT1021.002

Three of the six carried a HIGH severity, and they are worth reading closely — they are where a real menuPass intrusion would be caught before the pivot. The two MED alerts are the backdoor itself, and the LOW is the lateral-prep tell. Here is how ONYX read each of the load-bearing ones.

Suspicious New Service Creation — ALR-175448 · T1543.003

This Sigma rule keys on service-creation telemetry — a new service registered through the service control manager, visible both as a Sysmon process-creation event for sc.exe and as the corresponding Windows service-installed record. It is rated HIGH because a brand-new service is both durable (it survives reboots) and powerful (it typically runs as SYSTEM). ONYX treated it as a persistence anchor and used it as one of the load-bearing signals when it assembled INC-55843.

File Decoded From Base64/Hex Via Certutil.EXE — ALR-175453 · T1140

The rule matches certutil invoked with a decode flag (-decode / -decodehex). Legitimate administrative use of certutil to decode files is rare, so the command line itself is the signal. Mapped to T1140 (Deobfuscate/Decode Files or Information), it is a strong indicator that a next-stage payload is being reconstituted on disk — which is why ONYX scored it HIGH and foregrounded it in the incident narrative as evasion riding alongside the persistence, rather than as an isolated utility run.

Security Privileges Enumeration Via Whoami.EXE — ALR-175451 · T1033

This detection fires on whoami executed with the /priv argument. On its own, whoami is benign; with /priv it is a deliberate check of what the current token can do, and in an attack sequence it is reconnaissance that precedes escalation or persistence. ONYX read it in context — immediately before an account was created and promoted — and that ordering is part of why the burst grouped into a single coherent incident rather than scattering into unrelated noise.

Account creation and promotion — ALR-175452 / ALR-175449

Two MED alerts capture the backdoor itself: a new local user created via Net.EXE (T1136.001) and that user added to the local Administrators group (T1098). Individually each is the kind of event a busy admin might generate; back to back, on a host that just enumerated its own privileges, they are a privileged backdoor being stood up. ONYX's value here is correlation — it is the pairing, and the company those two alerts keep, that elevates the pair above their MED baseline.

New detection types

Five of these fired for the first time in the campaign — the signals the earlier scenarios never generated: account creation (T1136.001), Administrators-group addition (T1098), service installation (T1543.003), SMB admin-share access (T1021.002) and certutil decoding (T1140) — the persistence-and-lateral-prep playbook, all caught.

Evidence

Rebuilding the causality tree

THRONE does not just list alerts — it reconstructs the chain that produced them. Every Sysmon process-creation event carries a ProcessGuid for the process and a ParentProcessGuid for the process that spawned it. Stitching child to parent across the whole burst rebuilds the execution tree exactly as it ran on the box.

For INC-55843 that tree roots at the interactive session on WIN-J50RP1JBGD4 and branches out through each Net.EXE, whoami.exe, sc.exe and certutil.exe invocation — the same six actions the kill-chain section walks through, now linked by their real parent-to-child GUID relationships rather than guessed at from timestamps. Where an action also leaves a second trail — the service-install record in the Windows System log, the account-creation and group-change records in the Security log, the outbound SMB connection on TCP 445 — those corroborating events hang off the same tree, so the incident reads as one story instead of a pile of coincidences.

Why the tree matters

Timestamps tell you what happened near each other; process GUIDs tell you what caused what. The parent-to-child lineage is what lets ONYX assert that the privilege check, the backdoor account, the service and the share mount belong to one actor and one session — and it is what an analyst needs to scope the blast radius without replaying the whole host by hand.

Why it matters

What is hard about this adversary

menuPass is difficult precisely because almost nothing it does is malware. Every action in this run is a legitimate Windows administrative capability, used the way a real administrator sometimes uses it. The detection problem is not "is this tool bad" — it is "is this the wrong hands, in the wrong order, on the wrong host."

Three things make that hard in practice. First, volume: accounts are created, services are installed and shares are mapped thousands of times a day across a real estate, so a rule that simply alerts on "a service was created" drowns the analyst. Second, sequence: the danger lives in the ordering — privilege check, then backdoor, then promotion, then persistence, then pivot — not in any single event. Third, stealth and patience: APT10 is content to move one hop at a time over weeks, so the signal is spread thin across time and hosts, and the pieces rarely arrive together where a human will notice them.

The finding from this run is that THRONE caught all six behaviours and, more importantly, ONYX reassembled them into one incident without an analyst connecting the dots. That is the difference that matters against a patient espionage actor: six low-context alerts are easy to dismiss one at a time; one incident that reads "a privileged backdoor was stood up and an admin share was mapped for the next hop" is not.

Defensive takeaways

What to do with this

Four concrete moves that make a menuPass-style persistence-and-pivot sequence expensive to run and easy to catch.

1 · Alert on account and group changes as a pair, not alone

A new local account is noisy; a new local account that is promoted into Administrators within seconds, on a host that just ran whoami /priv, is not. Correlate T1136.001 and T1098 — and weight them far higher when they arrive together. That pairing is the backdoor signature, and it is what ONYX leaned on to group INC-55843.

2 · Treat certutil decoding as hostile by default

Legitimate administrative use of certutil -decode is rare enough that it should be alerted on every time (T1140). The same discipline applies to the other signed binaries APT10 favours — run down certutil, bitsadmin and mshta usage and baseline who, if anyone, is allowed to use them at all.

3 · Monitor admin-share mounts between endpoints

Server-to-server admin-share traffic is often routine; a workstation mapping admin$ on a peer (T1021.002) is a lateral-movement tell. Baseline who legitimately reaches admin shares, and alert on the exceptions — this is the move that stops island-hopping at the first hop instead of the tenth.

4 · Keep full process lineage, not just alerts

The reason INC-55843 read as one story is that Sysmon captured ProcessGuid/ParentProcessGuid on every process. Deploy Sysmon (or an equivalent EDR) with process-creation, network and file-create logging, retain it, and make sure your pipeline preserves the parent-to-child lineage — it is what turns scattered alerts into a scoped incident.